FBI warns of online payroll scheme

September 19, 2018

After receiving several complaints of cybercriminals targeting online payroll accounts, the Federal Bureau of Investigation is urging the public to be cautious and vigilant.

The FBI’s IC3, an online portal for victims to report internet crimes to the FBI, got repeatedly complaints recently from employees in various industries that claimed their online payroll accounts were targeted.

The FBI said education, health care and commercial airway transportation institutions have been most impacted so far.

Cybercriminals typically target employees through phishing emails, the FBI said. The emails will give the cybercriminals access to the employee’s log-in credentials.

“Once the cybercriminal has obtained an employee’s credentials, the credentials are used to access the employee’s payroll account in order to change their bank account information,” the FBI said.

The suspects will often turn off any potential alerts regarding direct deposit changes so the employee isn’t immediately aware. Direct deposits will then be changed and redirected to an accounts controlled by the cybercriminal, the FBI said.

The FBI urges employees to alert their employers of this scheme. Employers are urged to educate their workforce.

Employees should hover their cursor over hyperlinks included in emails to view the actual URL, the FBI said. If the URL is not related to or associated with the company, do not click on it.

“Instruct employees to refrain from supplying log-in credentials or personally identifying information in response to any email,” the FBI said. “Direct employees to forward suspicious requests for personal information to the information technology or human resources department.”

The full news release with additional tips can be found at www.ic3.gov/media/2018/180918.aspx.

Any victims are encouraged to report criminal or suspicious activity to their local FBI field office and file a complaint with the IC3 at www.ic3.gov. If your complaint pertains to this particular scheme, note “payroll diversion” in the body of the complaint.

Update hourly